Ethical Hacker ICT Professionals
SaveWhat Does an Ethical Hacker Do?
Ethical hackers perform security vulnerability assessments and penetration tests in accordance with industry-accepted methods and protocols. They analyse systems for potential vulnerabilities that may result from improper system configuration, hardware or software flaws, or operational weaknesses.
Resource recommendations may include affiliate links. Learn more
Where Do I Start?
Computer Forensics
The process of examining and recovering digital data from sources for legal evidence and crime investigation.
Sign up to trackReady to go deeper? Pick up to 3 skills to focus on from the list below.
These are common skills for this role. Real-world experience matters more than ticking every box — use this as a guide, not a checklist.
Skills You Need to Become an Ethical Hacker
Essential Skills
Essential Skills
-
EssentialComputer Forensics knowledge
The process of examining and recovering digital data from sources for legal evidence and crime investigation.
-
EssentialCyber Attack Counter-measures knowledge
The strategies, techniques and tools that can be used to detect and avert malicious attacks against organisations' information systems, infrastructures or networks.
Recommended Books
5 books -
EssentialTools For ICT Test Automation knowledge
The specialised software to execute or control tests and compare predicted testing outputs with actual testing results such as Selenium, QTP and LoadRunner
-
EssentialWeb Application Security Threats knowledge
The attacks, vectors, emergent threats on websites, web applications and web services, the rankings of their severity identified by dedicated communities such as OWASP (Open Web Application Security Project).
-
EssentialSoftware Anomalies knowledge
The deviations of what is standard and exceptional events during software system performance, identification of incidents that can alter the flow and the process of system execution.
-
EssentialLegal Requirements Of ICT Products knowledge
The international regulations related to the development and use of ICT products.
-
EssentialPenetration Testing Tool knowledge
The specialised ICT tools which test security weaknesses of the system for potentially unauthorised access to system information such as Metasploit, Burp suite and Webinspect.
No book recommendations available yet.
-
EssentialAddress Problems Critically skill
Identify the strengths and weaknesses of various abstract, rational concepts, such as issues, opinions, and approaches related to a specific problematic situation in order to formulate solutions and alternative methods …
Course recommendations coming soon.
-
EssentialExecute ICT Audits skill
Organise and execute audits in order to evaluate ICT systems, compliance of components of systems, information processing systems and information security. Identify and collect potential critical issues and recommend solutions …
Course recommendations coming soon.
-
EssentialExecute Software Tests skill
Perform tests to ensure that a software product will perform flawlessly under the specified customer requirements, using specialised software tools. Apply software testing techniques and tools in order to identify …
Course recommendations coming soon.
-
EssentialMonitor System Performance skill
Measure system reliability and performance before, during and after component integration and during system operation and maintenance. Select and use performance monitoring tools and techniques, such as special software.
Course recommendations coming soon.
-
EssentialProvide Technical Documentation skill
Prepare documentation for existing and upcoming products or services, describing their functionality and composition in such a way that it is understandable for a wide audience without technical background and …
Course recommendations coming soon.
-
EssentialAnalyse The Context Of An Organisation skill
Study the external and internal environment of an organisation by identifying its strengths and weaknesses in order to provide a base for company strategies and further planning.
Course recommendations coming soon.
-
EssentialDevelop Code Exploits skill
Create and test software exploits in a controlled environment to uncover and check system bugs or vulnerabilities.
Course recommendations coming soon.
-
EssentialIdentify ICT Security Risks skill
Apply methods and techniques to identify potential security threats, security breaches and risk factors using ICT tools for surveying ICT systems, analysing risks, vulnerabilities and threats and evaluating contingency plans.
Course recommendations coming soon.
-
EssentialIdentify ICT System Weaknesses skill
Analyse the system and network architecture, hardware and software components and data in order to identify weaknesses and vulnerability to intrusions or attacks.
Course recommendations coming soon.
-
EssentialPerform Security Vulnerability Assessments skill
Execute types of security testing, such as network penetration testing, wireless testing, code reviews, wireless and/or firewall assessments in accordance with industry-accepted methods and protocols to identify and analyse potential …
Course recommendations coming soon.
Optional Skills (5 of 25 displayed)
-
OptionalInternet Governance knowledge
The principles, regulations, norms and programs that shape the evolution and use of internet, such as internet domain names management, registries and registrars, according to ICANN/IANA regulations and recommendations, IP …
Recommended Books
5 books -
OptionalInternet Of Things knowledge
The general principles, categories, requirements, limitations and vulnerabilities of smart connected devices (most of them with intended internet connectivity).
-
OptionalOrganisational Resilience knowledge
The strategies, methods and techniques that increase the organisation's capacity to protect and sustain the services and operations that fulfil the organisational mission and create lasting values by effectively addressing …
-
OptionalOutsourcing Model knowledge
The outsourcing model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of …
-
OptionalNessus knowledge
The computer program Nessus is a specialised ICT tool which tests security weaknesses of the system for potentially unauthorised access to system information, developed by the software company Tenable Network …
-
OptionalNexpose knowledge
The computer program Nexpose is a specialised ICT tool which tests security weaknesses of the system for potentially unauthorised access to system information, developed by the software company Rapid7.
-
OptionalWhitehat Sentinel knowledge
The computer program WhiteHat Sentinel is a specialised ICT tool which tests security weaknesses of the system for potentially unauthorised access to system information, developed by the software company WhiteHat …
-
OptionalInformation Security Strategy knowledge
The plan defined by a company which sets the information security objectives and measures to mitigate risks, define control objectives, establish metrics and benchmarks while complying with legal, internal and …
Recommended Books
2 books -
OptionalSaas (service-oriented Modelling) knowledge
The SaaS model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of …
Recommended Books
2 books -
OptionalICT Network Security Risks knowledge
The security risk factors, such as hardware and software components, devices, interfaces and policies in ICT networks, risk assessment techniques that can be applied to assess the severity and the …
Recommended Books
1 book -
OptionalICT Security Standards knowledge
The standards regarding ICT security such as ISO and the techniques required to ensure compliance of the organisation with them.
Recommended Books
2 books -
OptionalICT Security Legislation knowledge
The set of legislative rules that safeguards information technology, ICT networks and computer systems and legal consequences which result from their misuse. Regulated measures include firewalls, intrusion detection, anti-virus software …
Recommended Books
1 book -
OptionalLevels Of Software Testing knowledge
The levels of testing in the software development process, such as unit testing, integration testing, system testing and acceptance testing.
-
OptionalProxy Servers knowledge
The proxy tools which act as an intermediary for requests from users searching for resources e.g. files and web pages from other servers such as Burp, WebScarab, Charles or Fiddler.
-
OptionalHybrid Model knowledge
The hybrid model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of …
Recommended Books
2 books -
OptionalICT Encryption knowledge
The conversion of electronic data into a format which is readable only by authorized parties which use key encryption techniques, such as Public Key Infrastructure (PKI) and Secure Socket Layer …
-
OptionalOpen Source Model knowledge
The open source model consists of principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety …
Recommended Books
1 book -
OptionalInformation Confidentiality knowledge
The mechanisms and regulations which allow for selective access control and guarantee that only authorised parties (people, processes, systems and devices) have access to data, the way to comply with …
-
OptionalCyber Security knowledge
The methods that protect ICT systems, networks, computers, devices, services, digital information and people against illegal or unauthorised use.
No book recommendations available yet.
-
OptionalService-oriented Modelling knowledge
The principles and fundamentals of service-oriented modelling for business and software systems that allow the design and specification of service-oriented business systems within a variety of architectural styles, such as …
No book recommendations available yet.
-
OptionalManage IT Security Compliances skill
Guide application and fulfilment of relevant industry standards, best practices and legal requirements for information security.
Course recommendations coming soon.
-
OptionalPerform Project Management skill
Manage and plan various resources, such as human resources, budget, deadline, results, and quality necessary for a specific project, and monitor the project's progress in order to achieve a specific …
Course recommendations coming soon.
-
OptionalSolve ICT System Problems skill
Identify potential component malfunctions. Monitor, document and communicate about incidents. Deploy appropriate resources with minimal outage and deploy appropriate diagnostic tools.
Course recommendations coming soon.
-
OptionalDefine Security Policies skill
Design and execute a written set of rules and policies that have the aim of securing an organisation concerning constraints on behaviour between stakeholders, protective mechanical constraints and data-access constraints.
Course recommendations coming soon.
-
OptionalMaintain ICT Server skill
Diagnose and eliminate hardware faults via repair or replacement. Take preventive measures, review performance, update software, review accessibility.
Course recommendations coming soon.